-- admin.controller.wo — POST /admin/ch/:slug: title/body update, -- form-encoded, bearer-gated. Mechanism (bearer_token, constant-time -- ct_eq) is the framework's; POLICY — which routes, which token — is -- this app's, right here. No rendering: the answer is a redirect. use framework/http pub class AdminEdit { token: Text fn handle(req: Req) -> Resp { let got = bearer_token(req); if got == nil { return unauthorized(); } if ct_eq("${got}", self.token) == false { return unauthorized(); } let slug = req.params["slug"]; if slug == nil { return not_found(); } let hits = from c in Chapter where c.slug == slug take 1 select c; if len(hits) == 0 { return not_found(); } let f = form_values(req); if f == nil { return bad_request("body must be form-encoded (title, body)"); } let title = f["title"]; let body = f["body"]; if title == nil and body == nil { return bad_request("nothing to update"); } if title != nil { let t = trim("${title}"); if t == "" { return bad_request("title must not be empty"); } hits[0].title = t; } if body != nil { hits[0].body = "${body}"; } return redirect("/ch/${slug}"); } }